AWS Identity Center Identity Provider Change
Description
Detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.
Query · sigma
selection: eventSource: - sso-directory.amazonaws.com - sso.amazonaws.com eventName: - AssociateDirectory - DisableExternalIdPConfigurationForDirectory - DisassociateDirectory - EnableExternalIdPConfigurationForDirectory condition: selection
Known false positives
- Authorized changes to the AWS account's identity provider